VYPR

Dspy

by Stanford

pypi: dspy

Source repositories

CVEs (2)

  • CVE-2026-72742HigAug 11, 2026
    risk 0.49cvss 8.6epss 0.00

    DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed…

  • CVE-2025-12695MedNov 4, 2025
    risk 0.38cvss 5.9epss 0.00

    The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.